Daily briefing · July 27, 2026
CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress Stacks
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
July 27, 2026 brings a clear ATTENTION verdict: two vulnerabilities are under active exploitation, one of which — CVE-2026-16812, a perfect CVSS 10.0 in VeloCloud Orchestrator On-Prem — was flagged by VulnCheck before CISA confirmed it, signaling real-world attacker activity ahead of official acknowledgment. The day saw 426 new CVEs published, 25 of them critical, with the VeloCloud flaw standing alone as a confirmed KEV entry. Beyond that anchor threat, a cluster of critical RCE and privilege-escalation bugs across TeamCity, WordPress plugins, pheditor, phpMyFAQ, and SiYuan demand immediate triage from defenders.
Today’s brief
- CVE-2026-16812 (CVSS 10.0, KEV): VeloCloud Orchestrator On-Prem is being actively exploited — patch or isolate immediately.
- TeamCity (CVE-2026-63077, CVSS 9.8): unauthenticated RCE via agent polling protocol affects all pre-2026.1.3/2025.11.7 instances.
- Two pheditor critical flaws (CVE-2026-48030, CVE-2026-55579): hardcoded default credentials plus OS command injection equal trivial full server compromise.
- Brazil faces a surge of ransomware hits across energy, healthcare, finance, and agriculture — Section9 and Global Secret Group are the most active groups this cycle.
Critical highlights
1
A perfect CVSS 10.0 in VeloCloud Orchestrator On-Prem grants remote attackers unauthenticated access to privileged internal functionality, fully compromising confidentiality, integrity, and availability of the orchestrator and all managed data. Confirmed in both CISA KEV and VulnCheck KEV — the VulnCheck observation preceded official CISA confirmation, meaning exploitation was already occurring in the wild before the formal alert; this is the single most urgent patch of the day.
2
An unauthenticated stored XSS in Product Feed Manager (≤7.6.1) was observed by VulnCheck before any CISA acknowledgment, indicating active attacker interest; exploitation can lead to session hijacking or malicious script injection against site administrators without requiring any credentials.
3
An OS command injection in pheditor's terminal action handler lets any authenticated user bypass the TERMINAL_COMMANDS whitelist by injecting shell metacharacters into the 'dir' POST parameter, achieving full remote code execution on the host — a proof-of-concept exists, lowering the bar for exploitation significantly.
4
Pheditor ships with a hardcoded default password ('admin') with no forced change on first login; any internet-exposed deployment retaining defaults gives attackers immediate full access to file editing, upload, and terminal features — the existence of a PoC makes mass scanning likely.
5
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 allows unauthenticated remote code execution via the agent polling protocol — a critical exposure for any CI/CD pipeline exposed to untrusted networks, where compromise can cascade into the entire software supply chain.
6
CVE-2026-13714CVSS 9.8PoCaffects Realtyna Organic IDX plugin + WPL Real Estate The Realtyna Organic IDX + WPL Real Estate WordPress plugin (before 5.3.0) allows unauthenticated PHP file upload due to hardcoded credentials identical across all installations, enabling direct remote code execution; every site running the default configuration is fully exposed to unauthenticated attackers.
7
MemberGlut (WordPress plugin before 1.1.5) fails to validate user roles during front-end registration, allowing any unauthenticated visitor to self-register as an administrator and achieve complete site takeover — a PoC is available, making automated exploitation straightforward.
8
phpMyFAQ before v4.1.6 lets authenticated administrators write arbitrary PHP files by manipulating an upgrade configuration setting and uploading a malicious ZIP, turning a legitimate admin workflow into a remote code execution vector — relevant in environments where admin accounts may be shared or phished.
9
SiYuan desktop (before v3.7.2) is vulnerable to reflected XSS via a crafted siyuan:// deep link in the bazaar plugin readme handler; because the Electron renderer runs with full Node.js access, successful exploitation translates to arbitrary code execution on the victim's desktop — a particularly dangerous vector for knowledge-worker environments.
10
A stored XSS in SiYuan (before v3.7.2) allows users with editor permissions to inject unescaped onload handlers into Gallery and Kanban cover images, executing arbitrary code in the Electron renderer with full Node.js access when any user opens the affected document — a stealthy persistence and lateral-movement risk in collaborative note-taking environments.
Ransomware today
Brazil is the focal point of ransomware activity in this reporting period, with Section9 emerging as the most prolific group, striking targets across financial services, technology, agriculture, and other sectors. Global Secret Group claimed Sinop Energia (energy and utilities) and SPDM (healthcare), while arcusmedia hit Power Moendas and the blackwater group targeted msgas.com.br in the energy sector. Over the past 30 days, lockbit5 (49 BR victims), lockbit3 (39), and ransomhub (35) lead the broader ransomware landscape, with arcusmedia and thegentlemen each accounting for 20 Brazilian victims.
********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35arcusmedia 20thegentlemen 208base 20
Active groups & APTs
Several threat actor groups are currently being tracked with updated activity profiles, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victim counts are attributed to these actors at this time, their active monitoring status suggests operational readiness or reconnaissance phases that defenders — particularly in targeted sectors — should treat as elevated background risk.
Brazil focus
Brazil is experiencing a concentrated ransomware campaign wave, with Section9 hitting at least seven Brazilian organizations recently across financial services, technology, agriculture, and other sectors, and Global Secret Group targeting critical infrastructure (Sinop Energia) and healthcare (SPDM). The breadth of sectors — from energy to finance to food production — reflects an indiscriminate targeting posture that increases exposure risk for virtually any mid-to-large Brazilian organization regardless of industry.
******.net.brSection9 · Financial Services
******.com.brSection9 · Other
Sinop EnergiaGlobal Secret Group · Energy & Utilities
****.com.brSection9 · Technology
*****.com.brSection9 · Financial Services
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Organizations running VeloCloud Orchestrator On-Prem must apply the available patch or restrict external access immediately, as active exploitation is confirmed; simultaneously, teams should audit all TeamCity instances, WordPress plugin versions (particularly pheditor, Realtyna, and MemberGlut), and SiYuan desktop deployments for the critical flaws disclosed today. Given the number of hardcoded-credential and default-password issues in this batch, a sweep for factory-default configurations across all public-facing services is strongly advised.
With active exploitation already underway on a CVSS 10.0 vulnerability and a wave of critical RCE flaws published in a single day, now is the moment to validate which of these affected components actually exist in your environment — because attackers are already asking the same question.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →